An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions this can result in arbitrary code execution.
This issue impacts MongoDB Server v5.0 versions prior to 5.0.33, v6.0 versions prior to 6.0.28, v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-126021 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 May 2026, 13:06
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | |
| First Time |
Mongodb mongodb
Mongodb |
|
| References | () https://jira.mongodb.org/browse/SERVER-126021 - Patch, Vendor Advisory |
13 May 2026, 15:34
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 04:17
Updated : 2026-06-17 11:03
NVD link : CVE-2026-8053
Mitre link : CVE-2026-8053
CVE.ORG link : CVE-2026-8053
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-787
Out-of-bounds Write
